Junglewise Threat Intelligence

CVE-2026-27405: Magepeople WpBookingly missing authorization in access control

CVE-2026-27405 · Severity: medium · CVSS 6.5 · Published 2026-05-20

Vendors: Magepeople inc., MagePeople.

Executive brief

WpBookingly is a WordPress plugin used for managing service bookings and appointments. A security flaw in the plugin's access control allows users with certain elevated permissions to perform actions they should not be authorized to do. This could lead to unauthorized modifications of booking data or service disruptions, though it requires the attacker to already have an account with high-level privileges.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Magepeople inc. WpBookingly plugin for WordPress through version 1.2.9. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing specific functions. An attacker with high-level privileges (such as an Author) can exploit this over the network without user interaction to perform unauthorized administrative actions, potentially impacting the integrity and availability of the service. The issue is resolved in version 1.3.0.

Affected products

  • Magepeople inc. WpBookingly (Service Booking Manager) <= 1.2.9

Timeline

  • 2025-11-06: other: Reported by researcher Jitlada
  • 2026-05-20: advisory: Published by Patchstack and NVD
  • 2026-05-20: patched: Patch released in version 1.3.0

References